2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2020-7693MEDIUM5.3Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This ...
CVE-2020-5366MEDIUM6.5Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious us...
CVE-2020-12424MEDIUM6.5When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, a...
CVE-2020-15073MEDIUM5.4An issue was discovered in phpList through 3.5.4. An XSS vulnerability occurs within the Import Administrators section v...
CVE-2020-2031MEDIUM4.9An integer underflow vulnerability in the dnsproxyd component of the PAN-OS management interface allows authenticated ad...
CVE-2020-1982MEDIUM4.8Certain communication between PAN-OS and cloud-delivered services inadvertently use TLS 1.0, which is known to be a cryp...
CVE-2020-7140MEDIUM6.1A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a ...
CVE-2020-15600MEDIUM6.5An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
CVE-2020-8916MEDIUM5.5A memory leak in Openthread's wpantund versions up to commit 0e5d1601febb869f583e944785e5685c6c747be7, when used in an e...
CVE-2020-15599MEDIUM6.1Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.
CVE-2020-15095MEDIUM4.4Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The C...
CVE-2020-15035MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15034MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15033MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15032MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15031MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15030MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15029MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15028MEDIUM5.4NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary ...
CVE-2020-11882MEDIUM6.1The O2 Business application 1.2.0 for Android exposes the canvasm.myo2.SplashActivity activity to other applications. Th...
CVE-2020-15037MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15036MEDIUM5.4NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary Ja...
CVE-2020-15584MEDIUM5.5An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can trigger an out-of-bounds access a...
CVE-2020-15583MEDIUM5.5An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. StickerProvider allows dire...
CVE-2020-15582MEDIUM5.5An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 7885 chipsets) software. The Bluetooth...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now